Legal
Privacy Policy
Last updated: September 6, 2026
This Privacy Policy explains what information LETHI processes, why, who else sees any of it, for how long it is kept, and the choices you have. It applies to the LETHI Android application and the LETHI service.
1. Who we are
Controller (GDPR Art. 4(7); responsable del tratamiento under Argentine Ley 25.326 Art. 2):
- Registered address — Lourdes 746, Moron, Buenos Aires, 1708, Argentina
- Contact for privacy matters — support@lethi.net
- Argentine database registration (Ley 25.326 Art. 21) — registration pending
LETHI is a scam-protection assistant. You show it a message, a link or a screenshot, and it tells you what it thinks and what to do next. If you allow it, it also watches for scams in the messages your messaging apps notify you about, and warns you during a phone call if you are being steered towards your banking app or a remote-control app.
LETHI is not an emergency service. It does not read your screen, does not listen to your calls, and does not know where you are.
2. The short version
- We see the content you send us, and — only if you switch it on — the text of notifications from five messaging apps. There is no call recording, no reading of your screen, no location tracking, and no access to your contact list.
- Background protection is off until you turn it on, in Android’s own Settings, on two separate screens. You can turn it off there at any moment and we stop immediately: the permission is the switch, and we never keep a copy of your answer that outlives it.
- Before any text you submit leaves your phone, the app redacts one-time codes, PINs, CVVs, passwords and bearer tokens. That redaction happens on your device, and our server applies the same redaction again — plus card, CBU/CVU and IBAN numbers — before anything is stored or sent to a processor. Neither pass is a promise that no secret ever slips through; they are two filters, not a guarantee.
- We ask for your consent separately for each purpose. Only “terms and privacy” is required — the other two are off by default and you can change them at any time.
- You can export everything we hold and delete your account from inside the app. Neither is paid for, delayed, or hidden.
- You must be 18 or over to use LETHI.
3. What we collect, why, and on what legal basis
Legal bases are GDPR Art. 6(1). The Argentine equivalents are Ley 25.326 Arts. 5 and 11 (consent as the rule, with the contractual-relationship exception in Art. 5(2)(d)).
3.1 Account and profile
- Display name, email address, email-verification status — create and secure your account; sign you in (Art. 6(1)(b) — performance of the contract).
- Password (stored only as a salted hash by our backend) — authentication (Art. 6(1)(b)).
- Google account identifier and email, if you sign in with Google — authentication (Art. 6(1)(b)).
- Country and language you choose — give you the right rules, the right notice version and the right language (this is a choice you make, never inferred from your IP address or SIM) (Art. 6(1)(b)).
- Your confirmation that you are 18 or over — legal compliance; LETHI is not offered to minors (Art. 6(1)(c)).
We do not collect your date of birth, a public handle, a searchable profile, or anything that would let another user find you. There is nothing here to widen into a discovery surface.
3.2 Consent records
One record per purpose, never bundled (GDPR Art. 7(2); Recital 43). Each record stores the purpose, the version of the notice you were shown, whether you granted it, when, and the market whose notice applied.
- Terms — required; declining means closing the account.
- Privacy notice — required; declining means closing the account.
- Model improvement — off by default; can turn off.
- Marketing — off by default; can turn off.
Those four are the only consent purposes the service records, and terms and privacy are recorded separately rather than as one bundled acceptance. Transactional and safety messages are not a consent: an alert you configured, an email confirming your address and a notice that a version changed are the product doing what you asked it to, and they rest on the contract, not on permission you could withdraw while keeping the feature. There is no cross-case personalisation purpose, because there is no cross-case personalisation: each situation is analysed on what you showed us for it.
Consent to version 3 of this notice is not consent to version 4. When we publish a new version we ask again.
3.3 Content you submit for analysis
- Message text you paste, type or share into LETHI — produce a risk analysis (Art. 6(1)(b)).
- Images and screenshots you pick or share — same, after server-side text extraction (OCR) (Art. 6(1)(b)).
- Links you ask us to check — reputation lookup (Art. 6(1)(b)).
- The source app, when you share content from another app — provenance, so the analysis and the case say where the content came from (Art. 6(1)(b)).
Before text leaves your device, the app
replaces one-time codes, verification codes, PINs, CVVs/security
codes, passwords and Bearer tokens with markers
such as [OTP] and [PASSWORD]. This is
a client-side step; the redacted text is what is transmitted and
what is stored.
Images are a different case and you should know it. An image cannot be redacted on the device, because the text inside it has not been read yet. The raw image is uploaded to private storage that is not readable from the internet, the text is extracted there, and the same redaction is applied to the extracted text before the text is analysed or stored.
The raw original does not outlive processing. Concretely: the upload link your phone is given is valid for five minutes and once only; the moment the image has been processed a durable job deletes the original, retrying until it succeeds; and an upload that is never submitted is removed by the storage bucket’s own deletion rule shortly after that five-minute window. What survives is the redacted text and a note of what could not be read — never the picture. If extraction fails, we record that it failed and say so; a screenshot we could not read is never treated as one that contained nothing worrying. The app deliberately does not queue images for later when you are offline: queueing would mean writing your raw screenshot to disk, so an offline image submission fails with conservative guidance instead of being stored.
Audio, PDF and EML files are not accepted. There is no camera capture.
3.4 Analysis results, cases and evidence
The analysis result (risk level, explanation, signals, recommended action), the case it opens, the timeline of what happened, the outcome you record, and the itemised list of what is kept for that case. “What is kept” is visible to you in the app, item by item, and each item can be deleted on its own.
Legal basis: Art. 6(1)(b).
3.5 Chat with the assistant
Messages you send to the LETHI assistant and its replies. The same redaction applies before your message leaves the device.
When your phone has no working connection, the app can answer using a model that runs entirely on your device. In that mode nothing you type is transmitted. Legal basis: Art. 6(1)(b).
3.6 Trusted contacts and alerts
You do not hand us an address book to add a trusted contact. To add one you create an invitation link, which the app lets you share however you like — the sharing happens on your phone, through whatever messenger you choose, and we neither see the recipient nor learn how you sent it. The other person becomes your trusted contact only by opening that link and accepting it from their own LETHI account. Nobody who has not created an account themselves is named anywhere in our systems by the invitation.
One phone number, and you type it yourself. Once someone is your trusted contact, you can save the number you would call them on, so that when LETHI warns you about something serious it can offer “call them” as a single tap. That number is stored on our servers against that one relationship. It is yours to see and nobody else’s: your contact cannot read it, no other user can, and LETHI never sends anything to it — no SMS, no call, no message of any kind. There is no SMS channel in this product at all. The app opens your phone’s dialler with the number filled in; you place the call, or don’t. Saving a number is optional and the feature works without one; you can change or delete it at any time on the trusted-contact screen, and deleting it removes it from our servers.
- The invitation, its permission level, its status, and a one-way digest of its link — set up the relationship, and stop a link being reused or guessed (Art. 6(1)(b)).
- The relationship between two accounts and its level — enforce what each side can and cannot see (Art. 6(1)(b)).
- Alerts and their delivery state (requested / delivered / opened / failed) — show you honestly whether an alert actually arrived (Art. 6(1)(b)).
- Accounts you have blocked — stop someone re-inviting you (Art. 6(1)(f) — your own protection).
- The phone number you save for your trusted contact — offer you a one-tap call to them when a warning is serious (Art. 6(1)(f) — your interest, and theirs, in being reachable quickly in a fraud emergency).
An invitation link is single-use and expires after 72 hours. We store it as a one-way digest, so possessing our database does not yield a usable link. Repeated failed attempts on one invitation are counted and stop it.
A trusted contact never sees the content. They do not see your messages, your chats, your screenshots or your original evidence. There is no setting that turns that on. There are two permission levels — roughly “serious situations only” and “also when help is suggested” — and both control when your contact is told something happened, never what you submitted. A contact cannot resolve, edit or delete your cases. You can change the level or end the relationship at any time, and it takes effect on their very next request, not at their next sign-in.
You may have one active trusted contact, and be the trusted contact for one other person. This is a product limit, and it is also why there is no address book here to protect.
We do not read your phone’s contact list. The
MVP build does not request READ_CONTACTS. The
number described above is the only phone number anywhere in our
systems, and it gets there one way: you typed it.
If you are the trusted contact and want to know about that number. It is personal data about you that someone else gave us (GDPR Art. 14). We did not obtain it from you, we obtained it from the person who added you; we use it for nothing but showing them a call button; we disclose it to nobody; and we keep it only while your relationship with them exists.
You are told this before you accept an invitation — it is on the acceptance screen, above the button, next to what you will and will not see — because that is the last moment before the number can exist, and because the one thing we will not do is write to you about it: that would mean using the very number we say we never use. After that, two things are yours without asking anyone:
- What is held. Your own data export includes any number another account holds about you, in the same package as everything else. Settings → export.
- Erasing it. Either of you can delete it, at any time, and it is gone from our servers. You do not need the other person’s cooperation, and you can also ask us using the contact details in §12.
3.7 Devices and sessions
Session records (when the session was created, when it was last seen, and which one you are reading this on) and, if you enable notifications, a Firebase push token. Purpose: let you see where your account is signed in and sign other devices out immediately. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) (account security).
We do not store the tokens themselves. A session token is kept only as a one-way digest, so a copy of our database does not let anyone sign in as you; revoking a session deletes the row and takes effect immediately, on the next request. Your push token is stored encrypted, and looked up by digest — registration never writes the token in the clear.
Lock-screen previews stay generic. A push notification carries only “there is a LETHI alert” and its identifier. The risk level, the summary and anything you submitted stay inside the app, behind your device lock.
3.8 Product analytics — none, in this release
We collect no product analytics. There is no analytics endpoint on our servers, no third-party analytics SDK in the app, no advertising identifier, and no profiling of any kind. The app build contains an unused event tracker whose destination does not exist; its calls fail and are discarded, and nothing about your behaviour in the app reaches us.
What we do keep is operational telemetry about the service, not about you: request counts by route and status class, response times, queue outcomes, and provider availability. Its labels are a fixed list that contains no account identifier, no URL, no request or response body, no token and no IP address, so a person cannot be picked out of it. Server logs are correlated by a per-request identifier, and authorization headers are stripped from them.
If we ever start collecting product analytics, that is a new purpose, a new version of this notice, and — where the events would be tied to your account — a consent, not a silent extension of this one. Legal basis for the operational telemetry: Art. 6(1)(f), our legitimate interest in running a service that works.
3.9 Background protection — notifications, calls, and the warning on top
This section covers everything the app does when you are not looking at it. None of it happens until you grant it, and all of it stops the moment you revoke the grant.
What we read from notifications
- The text of notifications posted by five messaging apps — detect a scam in a message as it arrives, and warn you before you reply (Art. 6(1)(a) — your consent, given by granting Notification Access).
The five apps are WhatsApp, Telegram, Google Messages, Samsung Messages and Gmail. Every other notification on your phone is discarded before its text is read — your banking app, your health app, your calendar and everything else are not looked at.
Three limits, because they are the ones that matter:
- One-time codes, PINs, card security codes, passwords and tokens are stripped on your phone before anything is sent, and stripped again on our server before anything is stored.
- A notification that does not turn out to be a warning is not stored at all — not by the app, not by us. It is analysed and dropped.
- We never see the rest of the conversation. A notification carries the one message that arrived, not the chat it belongs to.
Messages written by other people. This is the part we would rather you read twice. A message we analyse was written by whoever sent it to you, and that person is usually not a LETHI user. They did not agree to anything.
We handle that by keeping their content to the minimum the warning needs: it is redacted before it leaves your phone, it is not stored unless it produced a warning to you, it is never used to build a profile of the sender, it is never used to train a model, and it is never shared with anyone other than the processors in §5 who perform the analysis. Our legal basis for the sender’s content is legitimate interests (Art. 6(1)(f)) — yours in not being defrauded, and the sender’s own, since the overwhelming majority of these messages are sent by the scammer, not by your family.
What we read during a phone call
- That a call is ringing, connected or has ended — recognise the window in which phone-based fraud happens (Art. 6(1)(a)).
- Which single app came to the foreground during a call — warn you if a caller is steering you into your banking app or a remote-control app (Art. 6(1)(a)).
We do not read the phone number, the call log, or any audio. The app holds no SMS permission and no call-log permission, and cannot record a call. Outside an active call, no app-usage data is read at all — we do not build a picture of which apps you use or when.
The warning drawn over other apps. When a detection is serious enough, LETHI draws its warning on top of whatever app you are in. It appears only in response to a detection on your own phone, contains only the warning and its two controls, and cannot be triggered by us remotely.
Turning it off. Notification Access and Usage Access are granted and revoked in Android’s Settings, not in our app. Revoke either and the corresponding detection stops at once. The app re-reads the real permission every time you open it and never trusts a stored copy — so it cannot go on claiming to protect you after you have withdrawn the grant.
Turning it off does not delete what a warning already produced; use the deletion controls in §8 for that.
3.10 What we still do not collect
No location of any kind. No contact list. No call audio, call log or phone numbers of callers. No SMS. No inventory of your installed apps. No screen contents. No advertising identifier, and no third-party analytics SDK.
4. Automated processing and AI
LETHI’s analysis is produced with the help of a large language model. This matters to you in three ways:
- It can be wrong. LETHI produces one of five outcomes and one of them is “not enough information”. It never tells you something is safe or legitimate, because it cannot know that.
- It does not make legally significant decisions about you. Nothing LETHI outputs restricts your access to a service, decides a credit or employment outcome, or produces a legal effect within the meaning of GDPR Art. 22. It is advice you are free to ignore, and the app is built so that you decide what to do.
- Your content is not used to train models unless you say so. The “model improvement” consent is off by default, and the service records it as its own decision rather than folding it into your acceptance of these documents. Our model, OCR and link-reputation vendors must be contractually bound not to train on our data before each is switched on (GDPR Art. 28(3); see §5).
If you disagree with an outcome you can tell us so in the app. That feedback routes to a human and never automatically changes the model.
5. Who we share it with
-
Amazon Web Services, Inc. — everything stored
by the service, as the host of it: the application containers,
the database, the cache, the private evidence bucket and the
secret store. Processor (Art. 28). United States — region
us-east-2(Ohio). - Resend (Plus Five Five, Inc.) — your email address and the authentication email itself — a confirmation code or a recovery link. Processor (Art. 28). United States.
- Google LLC — Firebase Cloud Messaging — your push token and the fact a generic alert notification was sent. Processor (Art. 28). United States.
- Google LLC — Google Sign-In, if you use it — your Google identifier and email. Independent controller for your Google account. United States.
- Have I Been Pwned (breach screening) — nothing that identifies you or your password. The first five characters of a hash of a password you are choosing, and nothing else — the service returns a list of matches and our server does the comparison. Your password never leaves our systems. Not a processor of your personal data.
The extraction vendor is the one to look at hardest, and we say so plainly: it is the only recipient that ever sees a raw screenshot, before any redaction can be applied to it. Its contract must forbid training, require deletion after processing, and be signed before that feature is turned on. Until then the app reports that image checks are unavailable rather than sending anything.
A note on the assistant’s own limits. The link-reputation vendor receives the link and we perform that lookup from our servers, never from your phone — a request from your own device would tell whoever sent you the link that a human read it.
We do not sell personal information, and we do not “share” it for cross-context behavioural advertising as those terms are defined in the CCPA/CPRA (Cal. Civ. Code §1798.140(ad), (ah)).
We disclose data to law enforcement only on a valid legal order, and we tell you unless we are legally forbidden to.
6. International transfers
If you are in the EEA or the UK, your data is transferred outside it.
The EU–US Data Privacy Framework remains valid but is under appeal before the CJEU (Case C-703/25 P) and US PCLOB oversight is currently suspended. We maintain SCCs as a fallback for every US recipient.
If you are in Argentina, transfers outside Argentina are governed by Ley 25.326 Art. 12.
Copies of the safeguards are available on request at support@lethi.net.
7. How long we keep it
- Raw images and other raw originals — deleted the moment processing finishes. An upload link is valid for 5 minutes; an upload never submitted is removed by the storage rule shortly after it expires.
- Account, profile — while your account exists.
- Consent records — while your account exists, and after it closes, as proof of what you agreed to (GDPR Art. 7(1) accountability).
- Analyses, cases, evidence items — while your account exists, or until you delete them individually.
- Notification text that produced no warning — not stored. Analysed in memory and discarded.
- Notification text behind a medium or high warning — kept as part of the case it created, on the same terms as anything else in §3.4 — deletable individually, and gone when your account closes.
- That a call-risk window was open — kept with the detection it produced. Never the number, never the audio.
- Chats with the assistant — 30 minutes. A conversation is ephemeral by design: there is no chat history, no endpoint that lists past conversations, and nothing to reopen. What survives a conversation is only what became a case.
- Trusted relationships and blocks — until you end the relationship, or you close your account.
- The phone number saved for a trusted contact — until you delete it, you end that relationship, or you close your account — whichever comes first.
- Invitations — 72 hours, then they expire. Stored as a one-way digest.
- Sign-in sessions — an access token lasts 15 minutes and a refresh token 30 days; a revoked session’s row is deleted immediately. Email confirmation and recovery codes last 1 hour; a re-authentication challenge lasts 10 minutes and is single-use.
- Push tokens — until you sign the device out or the app is uninstalled. Stored encrypted.
- Product analytics — not collected. See §3.8.
- Data exports — a built export stays retrievable for 7 days, then it is gone and you request a new one.
Two things deliberately outlive your account, and neither describes you. The record that a deletion was requested and completed survives it, because a deletion with no evidence that it happened is not one we could prove to you or to a regulator; after the erasure that record identifies its subject only by a one-way digest, not by your account, your name or your email. The same is true of the audit entries covering the deletion itself.
When you delete your account we revoke every trusted contact’s access first, and only then cascade the deletion — so nobody keeps a view of data that is on its way out.
8. Your rights
Everywhere
- Access and portability — export everything we hold, from Settings, in a machine-readable form (GDPR Arts. 15, 20).
- Rectification — correct your profile in the app (Art. 16).
- Erasure — delete individual evidence items, individual cases, or your whole account, from the app (Art. 17). Deleting an evidence item deletes it for everyone who could see it, including your trusted contact. The app says so before you confirm.
- Withdraw consent — the three optional purposes are switches in Settings, and turning one off takes effect immediately, server-side (Art. 7(3)).
- Object to processing based on legitimate interests (Art. 21).
- Restriction of processing (Art. 18) — write to support@lethi.net.
- Revoke a session — sign any other device out immediately, from Settings.
Export and account deletion are never premium features and are never deferred. Changing your email address or password, exporting, and deleting your account all ask you to prove it is really you first, by re-entering your password or re-authenticating with Google — a signed-in phone that has been left unlocked is not enough for any of the four.
Export and deletion are queued and then carried out, rather than completed inside the tap: both run as durable jobs that survive a restart, so a request cannot be half-done. You can see the state of your request in the app. Deleting your account removes it from our live systems; §7 says what survives and why, and backups age out on their own schedule.
If you are in the EEA or the UK
You may lodge a complaint with your supervisory authority (GDPR Art. 77). In the UK, the ICO (ico.org.uk).
If you are in Argentina
You have the rights of access, rectification, updating and suppression under Ley 25.326 Arts. 14–16. The first access request in any six-month period is free. You may complain to the Agencia de Acceso a la Información Pública (argentina.gob.ar/aaip).
If you are in California
You have the rights to know, delete, correct, and to opt out of sale/sharing and of certain uses of sensitive personal information under the CCPA as amended by the CPRA. We do not sell or share your personal information. We will not discriminate against you for exercising a right (Cal. Civ. Code §1798.125). To exercise a right, use the in-app controls or write to support@lethi.net. You may use an authorised agent.
Other US state privacy laws (Virginia, Colorado, Connecticut, Utah, Texas and others) grant broadly equivalent rights; we honour them through the same controls.
How to exercise a right
Use the controls in the app first — they are immediate. Otherwise write to support@lethi.net. We respond within one month (GDPR Art. 12(3)), extendable by two further months for complex requests, and within 45 days for CCPA requests. We may need to verify your identity before acting.
9. Security
- All traffic between the app and our servers uses TLS, and every connection to a processor is HTTPS.
- Sensitive strings are redacted before transmission and again before storage.
- Passwords are hashed with Argon2id and are never stored, logged or forwarded in a form anyone can read back. When you choose a password we check it against a public breach corpus without sending it anywhere: only the first five characters of its hash leave our systems.
- Sign-in tokens are opaque random values stored as one-way digests, not self-contained tokens that carry their own permission. That is what makes revocation real: deleting the row ends the session on the next request, everywhere, immediately.
- Sensitive actions are rate-limited, and repeated failed attempts on an invitation stop it.
- Sessions can be revoked immediately from any device you are signed in on.
- Access to production data is limited to staff who need it and is logged.
- Optional device-level lock uses the Android BiometricPrompt API. Your fingerprint or face template never leaves your phone and never reaches LETHI — the operating system tells us only whether the check passed.
- Android backup of app data is disabled.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we notify our supervisory authority within 72 hours (GDPR Art. 33) and notify you without undue delay where the risk is high (Art. 34).
10. Children
LETHI is for adults. You must confirm you are 18 or over to create an account. We do not knowingly collect data from anyone under 18, we run no flows directed at children, and if we learn we hold a minor’s data we delete it. This closes GDPR Art. 8 rather than engaging it.
11. Changes to this policy
We version this notice. The current version is served by our backend, per language, and each consent record stores the exact version it was given against. When we make a change that affects you we raise the version and ask for your agreement again — we do not treat silence as acceptance, and the service treats an account whose latest consent is against an older version as one that has not finished agreeing. Consent to version 3 is not consent to version 4, in the code as well as here.
12. Contact
support@lethi.net · Lourdes 746, Moron, Buenos Aires, 1708, Argentina